Splunk Search

Heavy Forwarder Search

fmcgheeSplunk
Splunk Employee
Splunk Employee

i have a need to search the HWF for the apps that are currently used frequently and also which apps are sending data to indexers. 

 

Context - Upgrade readiness app has identified several apps that are not supported or in need of upgrade. Need to see if these apps are needed any longer and can be removed or truly need to be upgraded prior to the Splunk version upgrade of the HWF. 

Labels (3)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Well, it's not apps that send data, it's your forwarders 😉

But seriously - for data originating on this forwarder, you can just check which inputs are enabled and which are disabled so you can at least verify which inputs are definitely "not needed. Unfortunately, maybe short of some heavy debug, there is not even possible to know which way the event passed through so if you have HF processing data from some set of UF unless you know which UF's are supposed to output to this particular HF, you can't tell it from the resulting indexed event.

Having said that - if you're asking in context of upgrading to python3 and we're talking about HF, you probably mean which modular inputs are in use. I'd just do a btool inputs list and check which ones are enabled.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...